Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor White Shark Systems Project Subscribe
Filtered by product White Shark Systems
Total 9 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-20470 1 White Shark Systems Project 1 White Shark Systems 2022-09-29 5.0 MEDIUM 5.3 MEDIUM
White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability.
CVE-2020-20467 1 White Shark Systems Project 1 White Shark Systems 2022-09-29 6.4 MEDIUM 6.5 MEDIUM
White Shark System (WSS) 1.3.2 is vulnerable to sensitive information disclosure via default_task_add.php, remote attackers can exploit the vulnerability to create a task.
CVE-2020-20466 1 White Shark Systems Project 1 White Shark Systems 2021-06-23 7.5 HIGH 9.8 CRITICAL
White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can modify the password of any user.
CVE-2020-20468 1 White Shark Systems Project 1 White Shark Systems 2021-06-23 4.3 MEDIUM 6.5 MEDIUM
White Shark System (WSS) 1.3.2 is vulnerable to CSRF. Attackers can use the user_edit_password.php file to modify the user password.
CVE-2020-20469 1 White Shark Systems Project 1 White Shark Systems 2021-06-23 5.0 MEDIUM 7.5 HIGH
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the log_edit.php files failing to filter the csa_to_user parameter, remote attackers can exploit the vulnerability to obtain database sensitive information.
CVE-2020-20471 1 White Shark Systems Project 1 White Shark Systems 2021-06-23 9.0 HIGH 8.8 HIGH
White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can exploit this vulnerability to escalate to admin privileges.
CVE-2020-20472 1 White Shark Systems Project 1 White Shark Systems 2021-06-23 5.0 MEDIUM 5.3 MEDIUM
White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does not have an authentication operation. Remote attackers can obtain username information for all users of the current site.
CVE-2020-20473 1 White Shark Systems Project 1 White Shark Systems 2021-06-23 5.0 MEDIUM 7.5 HIGH
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, control_project.php, default_user.php files failing to filter the sort parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.
CVE-2020-20474 1 White Shark Systems Project 1 White Shark Systems 2021-06-23 5.0 MEDIUM 7.5 HIGH
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser.php files failing to filter the csa_to_user parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.